Pre-booking open · NyxShield and NyxAssure→

Find what's exploitable.Prove it's fixed.

NyxShield finds what an attacker would and retests every fix. NyxAssure turns that evidence into SOC 2 and ISO 27001 readiness.NyxShield pentesting and NyxAssure SOC 2 / ISO 27001 readiness.

FindingsTargetsReports
Your pentester is verifying a finding
Released to client3 findings
nyxassureReport → evidence CC4.1 · A.8.8
6.5
JWT still accepted after logoutportal · CWE-613
in progress
3.7
Stack traces in 500 responsesadmin · CWE-209
open
3.1
HSTS header missingportal · CWE-319
resolved
A NyxSentinel penetration tester typing on her laptop
NyxShield · security assessment

Find what an attacker would. Prove it's fixed.

Human-led penetration tests for web apps and APIs. Findings are reproduced before release, tracked in your console, and closed only after our retest analyst confirms the fix.

  • coversWeb apps, REST and GraphQL APIs, cloud-hosted assets
  • methodOWASP Testing Guide and NIST SP 800-115, manual testing on top of automated scans
  • you getA live findings console, CVSS scoring, retests and an audit-ready report
FindingsTargetsexample data
9.8
SQLi in export filterNYX-0143 · Billing API
In Progress
8.1
BOLA on invoice lookupNYX-0142 · Billing API
Open
7.6
Stored XSS in notesNYX-0139 · Patient Portal
Patched
3.1
HSTS header missingNYX-0138 · Patient Portal
Resolved
Retest analystverifying fixes
NyxAssure · GRC and compliance

SOC 2 and ISO 27001 readiness, built on evidence you already have.

Connect the tools you run. NyxAssure maps what they prove to your controls and to the criteria an auditor checks, drafts your policies and keeps a risk register current.

  • connectsAWS, GitHub, Google Workspace, Microsoft, Jira, CrowdStrike, Apple
  • tracksEvidence facts, controls, framework criteria, a 5×5 risk register
  • pairs withNyxShield, whose reports and retests already count as evidence
ReadinessControlsexample data
SOC 2 Type II41 / 53
ISO/IEC 27001:202262 / 93
CC6.1MFA on two admin accountsnext
A.8.24Key rotation policy awaiting approvalyou
CC7.2Alert routing evidence from AWSauto
Compliance leadsigning off
early access · pre-booking open

Pricing goes public soon. You can hold your place now.

Join the list and we'll send a quote for your exact scope before we open to everyone. These are the people you'll work with.

pentester
retest analyst
compliance lead
your engineer
our price promise

The most competitive price on the market, for industry-standard work.

what would you like to book?
when do you need it?

No payment, no commitment. We only use your email to send your quote.

pre-booking
You're on the list.

A confirmation is on its way. Reply to it with anything we should know before the scoping call.

nyxshield
OWASP Testing Guide and NIST SP 800-115, with manual testing on top of automated scans
deliverables
Executive summary, technical report with CVSS scores, remediation roadmap, retests
nyxassure
Evidence mapped to SOC 2 and ISO 27001 criteria, AI-drafted policies with e-signature, a 5×5 risk register
commitments
NyxShield: CVSS ≥ 8.0 reported immediately, final report within 5 business days. NyxAssure: a readiness score against every criterion in scope.
questions

Before you pre-book.

Anything else goes to business@nyxsentinel.com, and a person answers.

Still deciding? Pre-book with no commitment and ask us anything on the scoping call.

Pre-book →

Testing is non-destructive by contract: no denial-of-service, no exploits that risk data loss or downtime, and no changes to your data. If anything looks unstable we stop, and your emergency stop phrase halts all active testing at any point.

Scanners find known patterns. They don't notice that your refund endpoint accepts negative quantities, or that changing one ID returns another customer's data. Our testers use tools for coverage, then spend their time on authorization, business logic and chained attacks. Every finding is reproduced before you see it, and fixes are retested.

Anything at CVSS 8.0 or higher is released to your console as soon as it's confirmed, and you're alerted at the same moment if you turned instant alerts on during onboarding.

If a customer or investor is asking for a pentest, start with NyxShield. If you're heading into SOC 2 or ISO 27001, NyxAssure handles evidence, controls, risks and policies, and your NyxShield results feed into it.

No. NyxAssure gets you ready: controls, evidence, risks and policies in one place, with a readiness score you can quote. The audit is done by an independent CPA firm for SOC 2 or an accredited certification body for ISO 27001, which the standards require.

You answer one questionnaire and NyxAssure drafts the full set. You edit and approve each one, every save is versioned, and approved policies go out for e-signature and to your staff.

We're in early access. Pre-book and we'll quote your exact scope. We promise the most competitive price on the market for industry-standard work.

Evidence, credentials and logs are encrypted and securely deleted within 30 days of the engagement ending. Your reports and dashboards stay available to your authorised users.